CVE-2018-2007: Weak Encryption
Published Apr 29, 2019
·Updated
IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 155078.
Affected Software
1 affected component
IBM API Connect>=2018.1.0<=2018.4.1.2
Event History
Apr 29, 2019
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2007?
The severity of CVE-2018-2007 is considered to be high due to the potential for an attacker to decrypt sensitive information.
2
How do I fix CVE-2018-2007?
To fix CVE-2018-2007, upgrade IBM API Connect to a version that uses stronger cryptographic algorithms.
3
What versions are affected by CVE-2018-2007?
CVE-2018-2007 affects IBM API Connect versions 2018.1 and 2018.4.1.2.
4
What type of vulnerability is CVE-2018-2007?
CVE-2018-2007 is a cryptographic vulnerability that allows for the decryption of sensitive information.
5
Can CVE-2018-2007 be exploited remotely?
Yes, CVE-2018-2007 can potentially be exploited remotely if the attacker can access the affected system.